A data breach notice doesn't prove that someone has already stolen your identity. It does mean you should check what information was exposed and act before a problem appears. Verify the notice through an official channel, secure affected accounts, review your credit, financial, and healthcare records, and consider a credit freeze if your Social Security number or other identity data was involved.
The response depends on the data category. A stolen payment-card number calls for contacting the issuer and watching transactions. Exposed medical information calls for reviewing insurance claims and explanation of benefits statements. A compromised password requires an immediate change anywhere it was reused, followed by stronger account security.
What a data breach means for consumers
A data breach is unauthorized access to or disclosure of information held by a company, government agency, health plan, or service provider. It doesn't automatically show that criminals used your information.
A breach notice should identify:
- The information involved, such as your name, address, Social Security number, account number, payment-card data, or health information
- When the incident occurred and when it was discovered
- Whether your specific information was affected
- What monitoring, reimbursement, or other assistance is available
- How to contact the organization through an official channel
A large breach isn't automatically a larger personal risk. The exposed data category determines which accounts and records you should protect first.
Match your response to the information exposed
| Information exposed | Main risk | First step |
|---|---|---|
| Social Security number, date of birth, and address | New-account fraud or identity theft | Place a freeze with all three credit bureaus |
| Payment-card number | Unauthorized purchases | Contact the card issuer and monitor transactions |
| Bank-account or payment credentials | Unauthorized transfers or account takeover | Contact the financial institution promptly |
| Email address and password | Takeover of email and connected accounts | Change the password everywhere it was reused and enable multifactor authentication |
| Medical records, member IDs, or claims data | Medical identity theft, incorrect claims, or privacy harm | Review explanation of benefits statements and contact the health plan |
| Employee or tax information | Employment or tax-related identity fraud | Follow the notice instructions and report suspicious activity |
What to do after receiving a breach notice
1. Verify the notice and save its details
Scammers can use a real breach as a reason to send a fake alert. Don't click a link in an unexpected email or text. Instead, type the organization's website into your browser or use a phone number from a statement, card, or official website.
Save the notice, including:
- The organization that sent it
- The date of the notice
- The incident or reference number
- The data categories involved
- The deadline for accepting monitoring or other assistance
- Instructions for contacting the organization
If the notice is vague, ask which information about you was involved. Record the date, representative's name, and case number for each conversation.
2. Secure accounts and payment methods
Change the password for an affected service, and change it anywhere else you reused it. Start with email, banking, payment apps, and health-plan accounts because access to those accounts can expose other information. Use a different password for every important account and turn on multifactor authentication where available.
Contact a bank or card issuer promptly if account credentials or payment-card information may have been exposed. Review recent and future transactions, not only the balance shown today. If you see an unfamiliar charge or transfer, use the issuer's fraud-reporting process and the number on your card or its official website.
Don't provide one-time codes, passwords, or account numbers to someone who calls claiming to be a breach investigator. End the call and contact the company through a trusted number.
3. Freeze your credit when identity information is exposed
A security freeze restricts access to your credit report and can help stop someone from opening new credit in your name. A freeze is free and remains in place until you ask the credit bureaus to remove it.
You must request a freeze separately from:
- Equifax
- Experian
- TransUnion
The FTC's credit freeze and fraud alert guidance explains the process and links to the three credit bureaus. You can also review USAGov's instructions for placing or lifting a credit freeze.
A freeze won't close existing accounts or prevent every kind of fraud. It doesn't stop someone from using a stolen card number, impersonating you to a healthcare provider, or taking over an already-open online account.
If you apply for a loan, apartment, utility service, or another product that requires a credit check, you'll need to lift the freeze temporarily or provide the appropriate access details. USAGov says online or phone freeze requests generally must be processed within one business day. Requests sent by mail can take up to three business days. Online or phone requests to lift a freeze generally must be processed within one hour.
4. Consider a fraud alert
A fraud alert asks businesses to take additional steps to verify your identity before extending new credit. It's less restrictive than a freeze and may be useful if you suspect identity theft but need to apply for credit soon.
You can request an initial fraud alert from one credit bureau. Experian says it will notify Equifax and TransUnion when you request an alert through its service. Read the Experian freeze and fraud alert instructions for its current process.
A fraud alert doesn't block access to your credit report, guarantee that every fraudulent application will be rejected, or monitor existing bank, card, or medical accounts. If your Social Security number was exposed, a freeze provides a stronger barrier against many new-credit applications.
5. Check credit, financial, and medical records
Review your credit reports for:
- Accounts you don't recognize
- Hard inquiries you didn't authorize
- Incorrect addresses or employers
- Collection accounts tied to unfamiliar debts
- Changes to account limits or balances
Use AnnualCreditReport.com, the federally authorized source for free credit reports. The FTC also recommends regularly checking what appears in your reports.
For a payment or bank breach, review statements and transaction histories. For a health-data breach, review explanation of benefits statements and insurer claim records. An unfamiliar account, charge, treatment, prescription, or claim can be a sign of identity theft.
6. Report suspected identity theft
If you find an account or transaction you don't recognize, contact the company that handles it and use its fraud-reporting process. Ask what documents it needs, keep copies of everything you submit, and note when you reported the problem.
Report suspected identity theft through the FTC's identity theft reporting service. An FTC identity theft report can help organize the response and may be requested by a credit bureau, creditor, or other organization.
If the issue involves a credit bureau or financial company and you can't resolve it directly, review the Consumer Financial Protection Bureau complaint process. A complaint doesn't replace contacting the company or reporting identity theft, but it creates a separate record of an unresolved consumer problem.
Major data breach examples and their consumer lessons
These incidents show why the response should match the exposed data. Public investigations and affected-person notices can change over time, so use the notice sent to you, not a news summary, as the final word about your information.
Equifax: a preventable vulnerability and long-lasting identity risk
The 2017 Equifax breach involved highly sensitive personal information. It became a major example of why organizations need accurate asset inventories, timely security patches, and clear breach notifications.
For consumers, the lasting risk is different from a stolen card number. An issuer can replace a payment card, but replacing a Social Security number isn't a comparable solution. Identity information may remain useful to criminals long after the original incident.
The Federal Trade Commission says the Equifax settlement included up to $425 million to help affected consumers. The settlement page lists January 22, 2024, as the claim deadline, so consumers shouldn't assume they can submit a new claim now. It also says affected consumers can receive seven free Equifax credit reports per year through 2026 through AnnualCreditReport.com. Use the FTC's Equifax settlement information rather than an email or unofficial claim website.
Target: a vendor account reached payment systems
The 2013 Target breach is a well-known example of third-party access creating a consumer payment risk. Attackers used credentials connected to a vendor and reached systems that processed payment cards.
The practical lesson is to monitor payment accounts connected to a retailer even when the initial compromise occurred at a contractor. If you see an unfamiliar transaction, contact the card issuer through the number on the card or its official website. Don't wait for a breach-monitoring service to identify every fraudulent charge.
Capital One: cloud access can expose application data
The 2019 Capital One incident showed that a cloud breach doesn't always involve a simple public-storage mistake. An application vulnerability and improperly controlled cloud permissions were used to access stored application information.
People who applied for financial products should read the organization's notice carefully. It may identify different groups of people and different data elements. If a Social Security number was involved, use a credit freeze. If only contact information was exposed, be especially cautious about convincing phishing messages that appear to come from a bank or lender.
SolarWinds: a supply-chain incident may not affect every user equally
The SolarWinds incident involved malicious code distributed through Orion software updates. It demonstrated how an organization can be affected through software supplied by a trusted provider.
It also shows why consumers shouldn't assume that every person connected to an affected organization had personal data exposed. A company may issue a security announcement even when only certain systems or customers were involved. Look for an individual notice that identifies your information before taking steps designed for Social Security number exposure.
MOVEit: one file-transfer flaw, many separate notices
The 2023 MOVEit campaign exploited a vulnerability in file-transfer software used by organizations and service providers. Because these systems can hold files for multiple clients, one software flaw can lead to many separate breach investigations and notices.
If your notice names a payroll company, school, employer, insurer, or other service provider, follow that organization's instructions. Ask which files contained your information and whether the notice concerns your records or only the provider's broader system. Keep the notice and its reference number in case you need to dispute an account later.
Change Healthcare: health-data breaches require more than credit monitoring
The 2024 ransomware incident involving Change Healthcare disrupted claims processing, pharmacy transactions, and other healthcare services. Public reporting and breach notices described identity, insurance, claims, and protected health information among the data that could be involved for some people.
A credit freeze can help prevent new credit accounts, but it won't show whether someone used your insurance member ID or submitted a medical claim in your name. Review explanation of benefits statements, insurer claim histories, provider bills, and prescription records. Report unfamiliar treatment or claims to your health plan and the provider's fraud or privacy department.
For incident-specific information, start with your notice, insurer, or healthcare provider. The U.S. Department of Health and Human Services also maintains Change Healthcare cybersecurity incident FAQs.
Credit freeze, fraud alert, and monitoring: what each one does
| Tool | What it does | What it doesn't do |
|---|---|---|
| Credit freeze | Restricts access to your credit report and helps block many new-account applications | Doesn't stop existing-account fraud, medical identity theft, phishing, or account takeover |
| Fraud alert | Tells businesses to take extra steps to verify your identity before extending new credit | Doesn't block access to your report or guarantee that fraud won't occur |
| Credit monitoring | Notifies you about certain changes, inquiries, or accounts | Can't prevent misuse by itself and may not cover medical or non-credit fraud |
| Account review | Helps you spot unauthorized charges, claims, bills, and transactions | Requires you to check statements and report problems promptly |
You can use more than one tool. Someone whose Social Security number was exposed may freeze all three credit reports, enroll in available monitoring, and review existing financial and healthcare accounts. Someone whose payment-card number was exposed may need issuer contact and transaction monitoring, but not a credit freeze unless other identity information was also involved.
What breach settlements and free monitoring do not mean
A settlement, fine, or monitoring offer doesn't automatically reimburse every affected person. Eligibility, claim deadlines, and covered losses depend on the specific program.
Free monitoring also isn't the same as protection from identity theft. It may alert you after certain information appears in a credit file, but it can't stop a fraudulent medical claim, a phishing attack, or misuse of an existing account.
Before accepting an offer:
- Confirm the program on the organization's official website or a government agency's website.
- Don't pay a third party to submit a claim unless you've independently verified the service and its terms.
- Check whether enrollment has a deadline.
- Read what the monitoring service covers and how long it lasts.
- Don't provide a password, one-time code, or bank-login information to claim a benefit.
Prevention lessons consumers can use
- Use unique passwords for email, financial, healthcare, and shopping accounts.
- Turn on multifactor authentication, especially for email and financial accounts.
- Keep a credit freeze in place when you aren't applying for new credit.
- Limit the personal information you provide when a service doesn't need it.
- Review bank, card, credit, and healthcare records on a regular schedule.
- Be skeptical of messages that use a recent breach to demand urgent payment or account verification.
- Keep breach notices, dispute letters, and case numbers in one secure place.
The useful question after a breach isn't just "How many people were affected?" Ask instead, "What information about me was involved, and which account or report can show misuse?" Read the notice, take the step that matches the exposed data, and place a free freeze promptly when sensitive identity information is at risk.